Description
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47322
Related Vulnerabilities
CVE-2022-0654 Vulnerability in npm package requestretry
CVE-2020-28498 Vulnerability in maven package org.webjars.npm:elliptic
CVE-2023-26104 Vulnerability in npm package lite-web-server
CVE-2021-23413 Vulnerability in npm package jszip
CVE-2020-28500 Vulnerability in maven package org.fujion.webjars:lodash